using-git-worktrees

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands for environment management, including directory navigation, Git worktree operations, and executing project-specific test runners.
  • [EXTERNAL_DOWNLOADS]: The skill automates the download and installation of project dependencies using established package managers such as npm, pip, poetry, cargo, and go from their official registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local repository files to guide its execution logic, creating a potential attack surface if those files are malicious.
  • Ingestion points: CLAUDE.md, package.json, Cargo.toml, requirements.txt, pyproject.toml, go.mod.
  • Boundary markers: None; the skill implicitly trusts the repository content for its configuration.
  • Capability inventory: Git operations, file system modification (worktree creation), network access (via package managers), and arbitrary code execution (via npm test, pytest, etc.).
  • Sanitization: No validation or sanitization is performed on the values extracted from the configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM